Security News > 2023 > April

Hackers Flood NPM with Bogus Packages Causing a DoS Attack
2023-04-10 12:45

Threat actors are flooding the npm open source package repository with bogus packages that briefly even resulted in a denial-of-service attack. "The threat actors create malicious websites and publish empty packages with links to those malicious websites, taking advantage of open-source ecosystems' good reputation on search engines," Checkmarx's Jossef Harush Kadouri said in a report published last week.

Top 10 Cybersecurity Trends for 2023: From Zero Trust to Cyber Insurance
2023-04-10 11:38

Protect your website or app from DDoS attacks with Gcore's global DDoS protection service. Small and medium-sized enterprises may need help meeting the cyber insurance requirements that keep company data safe.

LLMs and Phishing
2023-04-10 11:23

Today's human-run scams aren't limited by the number of people who respond to the initial email contact. A smart scammer doesn't want to waste their time with people who reply and then realize it's a scam when asked to wire money.

Over 1 Million WordPress Sites Infected by Balada Injector Malware Campaign
2023-04-10 10:16

Over one million WordPress websites are estimated to have been infected by an ongoing campaign to deploy malware called Balada Injector since 2017. The massive campaign, per GoDaddy's Sucuri, "Leverages all known and recently discovered theme and plugin vulnerabilities" to breach WordPress sites.

Protecting your business with Wazuh: The open source security platform
2023-04-10 09:27

These solutions include firewalls, antiviruses, data loss prevention services, and XDRs. Wazuh is a free and open source security platform that unifies XDR and SIEM capabilities. The post Using the Wazuh SIEM and XDR platform to meet PCI DSS compliance shows how Wazuh plays an important role in maintaining PCI compliance for your organization.

CISA Warns of 5 Actively Exploited Security Flaws: Urgent Action Required
2023-04-10 06:25

The U.S. Cybersecurity and Infrastructure Security Agency on Friday added five security flaws to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation in the wild. This includes three high-severity flaws in the Veritas Backup Exec Agent software that could lead to the execution of privileged commands on the underlying system.

5G connections set to rise past 5.9 billion by 2027
2023-04-10 04:00

Global 5G wireless connections increased by 76% from the end of 2021 to the end of 2022, reaching up to 1.05 billion, and it will touch a mark of 5.9 billion by the end of 2027, according to Omdia and 5G Americas. Global 5G connections are forecast to accelerate in 2023, approaching 2 billion and reaching 5.9 billion by the end of 2027.

#5G
Cybercriminals use simple trick to obtain personal data
2023-04-10 03:30

People reveal more personal information when you ask them the same questions a second time - according to new research from the University of East Anglia. The research team say that understanding why people disclose personal data could help inform measures to address the problem.

MSPs urged to refine security solutions in response to growing SMB needs
2023-04-10 03:00

About 90% of respondents hailed automation as a crucial technology for their business because it improves efficiency, allows them to take on more clients and generates more revenue by automating common processes like endpoint management, monitoring, patching, ticket resolution and even cybersecurity. 64% of the executive and 54% of technician respondents picked automation, including auto-remediation of tickets, as their top remote monitoring and management feature.

Microsoft PowerToys adds Windows Registry preview feature
2023-04-09 20:45

We and our store and/or access information on a device, such as cookies and process personal data, such as unique identifiers and standard information sent by a device for personalised ads and content, ad and content measurement, and audience insights, as well as to develop and improve products. With your permission we and our partners may use precise geolocation data and identification through device scanning.